Security Engineer, Network Security
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Network Security, Systems Engineer, Network Engineer
- Security at Saronic is a force multiplier, not a blocker
- We’re looking for a Security Engineer to own network security end to end, including the corporate enterprise, our on-prem and production environments, our AWS cloud, and the communications and cryptography that keep autonomous vessels connected in contested, bandwidth-limited environments
- Today this work is handled part-time by engineers with other primary duties; you will own it
- You’ll partner with Information Technology, Enterprise Technology, Internal Apps, Infrastructure, Software, Mission Operations, Forward Deployed Engineers, Cloud Security, Product Security, and Security Operations and the teams building our vessels and their communications to secure every path from the operator to the vessel
- This is an opportunity to design network security across a uniquely broad surface (enterprise, on-prem, cloud, and vessel comms), solve genuinely hard problems in securing constrained maritime links, and build the automation that keeps segmentation enforced as the footprint scales
- Enterprise & On-Prem Network Security:
Own firewalls, segmentation and microsegmentation, wireless, DNS, VPN/ZTNA, and device hardening across a growing multi-site footprint, including corporate offices, data centers, and on-prem and production environments (i.e., Palo Alto, Cisco, Aruba; Global Protect, Tailscale/Wire Guard, IPsec) - Move the enterprise toward zero-trust access and retire flat-network and legacy-VPN patterns
- Cloud Network Security:
Design secure network architecture in AWS (commercial and Gov Cloud): VPC segmentation, private connectivity, and egress control - Vessel Communications & Cryptography:
Secure all vessel networking and communications, including cellular (LTE/5G), RF and radio links, SATCOM, mesh networking, and line-of-sight and beyond-line-of-sight connectivity, along with the command-and-control paths to and from vessels and platforms such as Echelon - Own cryptography and key management for platform communications, protect data in transit and at rest, and design resilient, secure links over intermittent, contested, low-bandwidth, and high-latency conditions
- Network Observability & NOC:
Increase network visibility and observability (flow logs, telemetry, and monitoring) across enterprise, on-prem, and cloud, and partner with Information Technology to support the build-out of the Network Operations Center (NOC) - Automation & Monitoring:
Automate network security (segmentation-as-code, configuration validation) and support network-based
Ability to obtain and maintain a U.S. security clearance5+ years of hands-on enterprise network security experience, or an equivalent combination of experience and demonstrated ability
Strong L3-L7 fundamentals: routing/BGP, TCP/UDP, TLS/PKI, and DNSCloud network security experience (AWS VPC design and controls)
Designed and operated firewalls, segmentation, VPN, and wireless in production (i.e., Palo Alto, Cisco, Aruba; Global Protect, Wire Guard/IPsec)
Zero Trust / SASE / ZTNA architecture
Network observability and visibility tooling, and experience standing up or supporting a Network Operations Center (NOC)
Secure design of SATCOM, RF, cellular, or mesh links; software-defined radio and spectrum awareness; COMSEC and cryptographic key management
Network automation at scale through scripting and Infrastructure-as-Code Experience in defense, maritime, aerospace, or other high-assurance environments
Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies
Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)
Visual acuity to read screens, documents, and reports
Occasional standing and walking within the office
Prolonged periods of sitting at a desk and working on a computer
Manual dexterity to operate a computer keyboard, mouse, and other office equipment
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).